WO2015166185A1 - System for identifying a company by means of the website thereof - Google Patents
System for identifying a company by means of the website thereof Download PDFInfo
- Publication number
- WO2015166185A1 WO2015166185A1 PCT/FR2015/051151 FR2015051151W WO2015166185A1 WO 2015166185 A1 WO2015166185 A1 WO 2015166185A1 FR 2015051151 W FR2015051151 W FR 2015051151W WO 2015166185 A1 WO2015166185 A1 WO 2015166185A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- trusted
- party
- company
- information
- website
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1483—Countermeasures against malicious traffic service impersonation, e.g. phishing, pharming or web spoofing
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
- G06Q10/06—Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling
Definitions
- the object of the present invention relates to the identification systems of a company. More particularly, the object of the invention relates to a tool for identifying a business via its website and inform a third party of the security status of the website.
- WOT is a small program that can be added to an Internet browser. Whenever the user does a search or consult a website, WOT indicates whether the site is reliable or not. WOT is an automatic tool, in other words, Wot is a trust assessment robot that you can have about a website. WOT uses three robotic sources to judge web sites. These three WOT robotic sources contribute to the creation of an evaluation sheet for each existing website. Robotic sources allow: - the collection of the opinion of Internet users; - collecting the opinion of other Web Reputation systems; - collection of mass assessment.
- VTZilla Another Web Reputation tool, named VTZilla, makes it possible to have a file scanned by a multi-antivirus service before downloading it.
- VTZilla is an additional module to a browser, written by VirusTotal, which allows to have the opinion of dozens of computer security companies, antivirus publishers, on the site where a download comes from and analyze a download, by several dozens of antivirus, before downloading.
- the object of the present invention is to overcome the disadvantages of the state of the art, and, in particular, to make a simple and reliable tool available to users so that they can identify the company owner of the website on which they surf with a simple click on a dynamic seal.
- the objective of the present invention is to present a simple and reliable and fun solution enhancing the safety of users by raising awareness of the fight against cybercrime.
- the invention provides a dynamic identification system via a company website, comprising: - a first module for registering and recording information of said company via a form from a trusted third party website;
- a second module for displaying information stored in a database of said trusted third party
- system further comprises a dynamic seal provided by said trusted third party and integrated (preferably manually) on the company's website so that a user using said dynamic seal can access the stored information of the company in the database of said trusted third party; in that said dynamic seal is clickable by said user so that an https protocol redirects said user to an application server belonging to said trusted third party and in that said trusted third party comprises means able to approve the information recorded by the company as well as storage means configured to store said information in its database after approval.
- the purpose of the system is also to give the audit reflex to users: where to check? what to check? Why ? [0010] Clickable means that there is an interaction between a user and the website on which there is the seal.
- the dynamic seal is integrated on the company's website by means of an application programmed by the trusted third party so that said dynamic seal can interact with a browser of a user, a surfer on said site. web. More specifically, it is the manual addition, for example by a technician, of a line of code to the code of the homepage of the website.
- the identification system further comprises a JDBC interface able to connect the application server to a data server of said trusted third party to extract information concerning the state of activity of the structure. owner of the company's website.
- an SSL certificate makes it possible to secure transactions between the user's web browser and the application server of the trusted third party.
- the trusted third party comprises means for verifying the information provided by the company, from several sources of official information before being stored in the database of said trusted third party and to be made available immediately.
- the verification means daily checks the information stored in the database.
- the data server comprises means for securing data to guarantee the integrity of the stored data.
- the invention also relates to the dynamic identification method of a website of a company implemented in the above system. The process is characterized by the following steps:
- FIG. 1 shows the technical architecture of a system for dynamically identifying a website of an enterprise according to the invention
- FIG. 2 shows the progress of a use case of the system of FIG. 1
- FIG. 3 shows the sequence diagram for the inscription part, illustrating the main interactions between the various actors and components of the system according to the invention.
- FIG. 4 shows the sequence diagram for the display part, illustrating the main interactions between the actors and components of the system according to the invention.
- FIG. 1 shows the technical architecture of the system for identifying a company through a website owned by 1 company audits according to the principle of the present invention.
- a website 10 belonging to a trusted third party 20 allows a company 2 to register. This website 10 is directly connected to the application server 1 1. The company registers via a telephone platform.
- a trusted third party advisor filled out a registration form on the website 10. For security reasons company 2 does not have direct access to the form of the website 10.
- a web server 4 belonging to the company 2 includes the website 1.
- the second module of the system according to the invention allows the display of information about the company 2 via a dynamic seal 3 clickable integrated to the website 1.
- the user 30 is redirected to an application server 1 1 belonging to the trusted third party 20.
- Said application server 1 1 connects to a data server 13 to access a database.
- the information is then visible to the user 30 who can thus check the state of activity of the structure owner of the website 1 of the company 2.
- the dynamic seal 3 allows the interaction between the browser of a user 30 and the website 1 of the company 2.
- the connection between the browser 31 of the user 30 and the Web server 4 of enterprise 2 is performed via the http or https protocol if enterprise 2 has secured its server 4 with the help of an SSL certificate.
- the connection to a site is either http or https, depending on the presence of an SSL certificate or not.
- the Web server 4 of the company 2 connects via the https protocol to the application server 1 1 of the trusted third party 20.
- the application server 1 1 of the trusted third party 20 connects to the data server 13 via a common interface to the database systems, JDBC.
- This JDBC interface allows applications installed on the application server to access data sources.
- the company 2 can at any time modify the information on the state of its business and its structure by sending an e-mail to the trusted third party 20.
- the information provided by the company 2 to the trusted third party 20 are verified by it from several sources of official information before being stored in the database 12 of said trusted third party 20 and be made available immediately.
- the trusted third party 20 carries out daily, from said sources of official information, checks of information stored in its database 12.
- the data server 13 is secure in order to guarantee the integrity of the stored data.
- an SSL certificate is set up to secure the transaction between the trusted third party 20 and the web browser 31 of the Internet user.
- an SSL certificate is installed on a trusted third party server, said certificate allows secure information exchange with the browser of the user.
- the possession of an SSL certificate by the trusted third party implies the following facts: - the transmission of data between the browser and the the website are encrypted; and the certificate issuing authority (OpenTrust) is authenticated and recognized on the browsers.
- OpenTrust certificate issuing authority
- Figure 2 shows the progress of a use case of the system of Figure 1.
- the company 2 fills out with the assistance of a counselor, the registration form 100 on the website 10 of the trusted third party 20.
- the company 2 records 101 and transmits the information concerning the state of its structure to this trusted third party.
- Verification 102 of the information is set up by the trusted third party 20 from official sources. In case this information does not fully correspond to the data recorded on the official sources, a request for update 103 is sent to the company 2 (client).
- an e-mail 104 is sent to the client 2 by the trusted third party 20 to inform him of the situation, otherwise the information will be stored in the database 12 of the trusted third party 20 and the dynamic seal 3, in the form of a 3 'deliverable program, is sent to the company 2.
- the company integrates 107 the dynamic seal 3 on its website 1.
- the trusted third party makes available to the users 30 the information on the structure that owns the website 1 of the company 2.
- a request 106 is sent to the trusted third party 20 which thus provides the stored information relating to the enterprise 2.
- Said information provides 11 are sent 108 by said trusted third party to the user 30.
- Figure 3 shows the sequence diagram of the registration module of the company 2 on the site of the trusted third party 20, illustrating the main interactions between the company 2 and the trusted third party. is registered 101 on the website 10 of the trusted third party, the information concerning its state of activity, this information is verified 102 by the trusted third party 20 and then saved 1 1 1 in the database 12 of the trusted third party via the application server 1 1. Finally, the source code of the dynamic seal 3 is sent to the company 2, from the application server 1 1, with all the documentation necessary for its deployment and its use.
- Figure 4 shows the sequence diagram of the display module and the main interactions between a user 30, the dynamic seal 3 and the trusted third 20.
- the development of registration and display modules is based on the MVC architecture and is performed under the J2EE platform, which allows to isolate different application layers.
- the system is able to verify information based on several official sources of information to ensure the veracity of the information provided. In addition, availability and accessibility is guaranteed for a large number of simultaneous connections.
- the system aims to display information on the owner structure of a website belonging to a company.
- This information informs the state of activity of said structure, in other words, it is a real identity card of the company.
- the system is intended to inform the user of the state of activity of a company via an icon installed on the website of said company.
- a user finds himself on a secure space when he clicks on the dynamic seal because the system is installed on a secure application server by an SSL certificate.
- the website of the company on which the dynamic seal is installed can also be secured by an SSL certificate in this case, the identification system according to the present invention can display information on the security level of the latter, (display of the SSL certificate data).
- the present invention further relates to a dynamic identification method of a website implemented in the above system and including the steps of registration and registration of a company with a trusted third party.
- the trusted third party verifies the information registered with the official sources. Then, it stores the recorded information that has been verified in its database 12.
- the trusted third party sends a 3 'copy of a dynamic seal 3 to the company 2.
- the integration of the dynamic seal 3 on the website 1 of the company 2 is done either by a manual installation of said dynamic seal via a person belonging to the trusted third party or through a provider of the company 2 having created or responsible for the maintenance of the website 1.
- a user who consults the website 1 of the company 2 can check the status of activity of said company by clicking on the dynamic seal 3.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
SYSTEME D'IDENTIFICATION D'UNE ENTREPRISE PAR L'INTERMEDIAIRE SYSTEM FOR IDENTIFYING AN ENTERPRISE THROUGH THE INTERMEDIARY
DE SON SITE WEB. OF ITS WEB SITE.
DOMAINE TECHNIQUE DE L'INVENTION TECHNICAL FIELD OF THE INVENTION
[0001] L'objet de la présente invention concerne les systèmes d'identification d'une entreprise. Plus particulièrement, l'objet de l'invention concerne un outil permettant d'identifier une entreprise de commerce par intermédiaire de son site internet et d'informer un tiers de l'état de sécurisation du site Web. The object of the present invention relates to the identification systems of a company. More particularly, the object of the invention relates to a tool for identifying a business via its website and inform a third party of the security status of the website.
ETAT DE LA TECHNIQUE DE L'INVENTION STATE OF THE ART OF THE INVENTION
[0002] De nos jours, il est facile à constater que la confidentialité des informations délivrées sur un site web est de plus en plus difficile à préserver, et que la cybercriminalité est en perpétuelle augmentation. Les sites internet des entreprises sont sécurisés par des moyens de sécurisation et des certificats SSL. Cependant, la vérification qu'un site Web est sécurisé reste difficile pour un utilisateur internaute. En effet, tous les utilisateurs internet n'ont pas le même degré de connaissance du domaine de l'internet. Nowadays, it is easy to see that the confidentiality of information delivered on a website is increasingly difficult to preserve, and that cybercrime is in perpetual increase. Business websites are secured by means of security and SSL certificates. However, verifying that a website is secure remains difficult for an Internet user. Indeed, not all internet users have the same level of knowledge of the Internet domain.
[0003]Vis-à-vis du problème de vérification de l'identité d'une entreprise sur le Web, des outils d'analyse existent. Par exemple, l'outil WOT, de Google, est un petit programme qui peut s'ajouter à un navigateur Internet. A chaque fois que l'utilisateur fait une recherche ou consulte un site internet, WOT indique si le site est fiable ou non. WOT est un outil automatique, en d'autres termes, Wot est un robot d'évaluation de la confiance que l'on peut avoir à propos d'un site Internet. WOT utilise trois sources robotisées pour juger les sites WEB. Ces trois sources robotisées WOT concourent à la création d'une fiche d'évaluation pour chaque site internet existant. Les sources robotisées permettent: - la collecte de l'avis des internautes; - la collecte de l'avis des autres systèmes de Réputation Web; - la collecte d'évaluation de masses. [0003] Vis-à-vis the problem of verifying the identity of a company on the Web, analysis tools exist. For example, Google's WOT tool is a small program that can be added to an Internet browser. Whenever the user does a search or consult a website, WOT indicates whether the site is reliable or not. WOT is an automatic tool, in other words, Wot is a trust assessment robot that you can have about a website. WOT uses three robotic sources to judge web sites. These three WOT robotic sources contribute to the creation of an evaluation sheet for each existing website. Robotic sources allow: - the collection of the opinion of Internet users; - collecting the opinion of other Web Reputation systems; - collection of mass assessment.
[0004] Un autre outil de Réputation Web, nommé VTZilla, permet de faire analyser un fichier, par un service multi-antivirus, avant de le télécharger. VTZilla est un module additionnel à un navigateur, écrit par VirusTotal, et qui permet d'avoir l'avis de plusieurs dizaines de sociétés de sécurité informatique, éditrices d'antivirus, sur le site d'où vient un téléchargement et d'analyser un téléchargement, par plusieurs dizaines d'antivirus, avant de le télécharger. [0004] Another Web Reputation tool, named VTZilla, makes it possible to have a file scanned by a multi-antivirus service before downloading it. VTZilla is an additional module to a browser, written by VirusTotal, which allows to have the opinion of dozens of computer security companies, antivirus publishers, on the site where a download comes from and analyze a download, by several dozens of antivirus, before downloading.
[0005] Les outils de "Web - Réputation" ou "Web confiance" existant actuellement, aussi efficaces qu'ils peuvent être, ne sont cependant pas facilement utilisables par un utilisateur non informaticien. De plus, ces outils, particulièrement WOT, sont basés sur une collecte d'avis d'internautes et ne peuvent donc pas constituer une source fiable permettant de déterminer si un site Web est de confiance ou non. [0006] L'objectif de la présente invention est de remédier à des inconvénients de l'état de la technique, et, en particulier, de mettre un outil simple et fiable à la disposition des utilisateurs afin qu'ils puissent identifier l'entreprise propriétaire du site internet sur lequel ils surfent par un simple clic sur un sceau dynamique. The tools of "Web - Reputation" or "Web trust" existing at present, as effective as they can be, however are not easily used by a non-computer user. In addition, these tools, particularly WOT, are based on a collection of user reviews and therefore can not be a reliable source for determining whether a website is trusted or not. The object of the present invention is to overcome the disadvantages of the state of the art, and, in particular, to make a simple and reliable tool available to users so that they can identify the company owner of the website on which they surf with a simple click on a dynamic seal.
EXPOSE DE L'INVENTION SUMMARY OF THE INVENTION
[0007] L'objectif de la présente invention est de présenter une solution simple et fiable et ludique renforçant la sécurité des usagers en les sensibilisant à la lutte contre la cybercriminalité. The objective of the present invention is to present a simple and reliable and fun solution enhancing the safety of users by raising awareness of the fight against cybercrime.
[0008] L'invention propose un système d'identification dynamique par l'intermédiaire d'un site web d'une entreprise, comprenant: - un premier module d'inscription et d'enregistrement des informations de ladite entreprise via un formulaire auprès d'un site web d'un tiers de confiance; The invention provides a dynamic identification system via a company website, comprising: - a first module for registering and recording information of said company via a form from a trusted third party website;
- un second module permettant l'affichage des informations stockées dans une base de données dudit tiers de confiance; a second module for displaying information stored in a database of said trusted third party;
caractérisé en ce que le système comprend en outre un sceau dynamique fourni par ledit tiers de confiance et intégré (de préférence manuellement) sur le site Web de l'entreprise de sorte qu'un internaute utilisateur via ledit sceau dynamique peut accéder aux informations stockées de l'entreprise dans la base de données dudit tiers de confiance ; en ce que ledit sceau dynamique est cliquable par ledit utilisateur de telle sorte qu'un protocole https redirige ledit utilisateur vers un serveur d'application appartenant audit tiers de confiance et en ce que ledit tiers de confiance comprend des moyens aptes à approuver les informations enregistrées par l'entreprise ainsi que des moyens de stockage configurés pour stocker lesdites informations dans sa base de données après leur approbation. characterized in that the system further comprises a dynamic seal provided by said trusted third party and integrated (preferably manually) on the company's website so that a user using said dynamic seal can access the stored information of the company in the database of said trusted third party; in that said dynamic seal is clickable by said user so that an https protocol redirects said user to an application server belonging to said trusted third party and in that said trusted third party comprises means able to approve the information recorded by the company as well as storage means configured to store said information in its database after approval.
[0009] L'objectif du système est aussi de donner le réflexe de vérification aux usagers : où vérifier ? que vérifier ? Pourquoi ? [0010]Cliquable signifie qu'il y a une interaction entre un utilisateur et le site Web sur lequel il y le sceau. The purpose of the system is also to give the audit reflex to users: where to check? what to check? Why ? [0010] Clickable means that there is an interaction between a user and the website on which there is the seal.
[0011]Particulièrement, le sceau dynamique est intégré sur le site web de l'entreprise au moyen d'une application programmée par le tiers de confiance de sorte que ledit sceau dynamique peut interagir avec un navigateur d'un utilisateur, internaute sur ledit site web. Plus précisément, il s'agit de l'ajout manuel, par exemple par un technicien, d'une ligne de code au code de la page d'accueil du site web. [0011] In particular, the dynamic seal is integrated on the company's website by means of an application programmed by the trusted third party so that said dynamic seal can interact with a browser of a user, a surfer on said site. web. More specifically, it is the manual addition, for example by a technician, of a line of code to the code of the homepage of the website.
[0012]Selon l'invention, le système d'identification comprend en outre une interface JDBC apte à connecter le serveur d'application à un serveur de données dudit tiers de confiance pour extraire des informations concernant l'état d'activité de la structure propriétaire du site web de l'entreprise. According to the invention, the identification system further comprises a JDBC interface able to connect the application server to a data server of said trusted third party to extract information concerning the state of activity of the structure. owner of the company's website.
[0013] Avantageusement, un certificat SSL permet la sécurisation des transactions entre le navigateur web de l'internaute et le serveur d'application du tiers de confiance. [0014] En outre, le tiers de confiance comprend des moyens permettant de vérifier les informations communiquées par l'entreprise, auprès de plusieurs sources d'informations officielles avant d'être stockées dans la base de données dudit tiers de confiance et d'être mises à disposition immédiatement. [0015] De plus, les moyens de vérification vérifient quotidiennement les informations stockées dans la base de données. [0013] Advantageously, an SSL certificate makes it possible to secure transactions between the user's web browser and the application server of the trusted third party. In addition, the trusted third party comprises means for verifying the information provided by the company, from several sources of official information before being stored in the database of said trusted third party and to be made available immediately. In addition, the verification means daily checks the information stored in the database.
[0016] Par ailleurs, le serveur de données comprend des moyens de sécurisation des données permettant de garantir l'intégrité des données stockées. [0017] L'invention concerne encore le procédé d'identification dynamique d'un site web d'une entreprise mis en œuvre dans le système ci-dessus. Le procédé est caractérisé par les étapes suivantes: Furthermore, the data server comprises means for securing data to guarantee the integrity of the stored data. The invention also relates to the dynamic identification method of a website of a company implemented in the above system. The process is characterized by the following steps:
- inscription en enregistrement des informations de ladite entreprise via un formulaire auprès d'un site web d'un tiers de confiance ; registration of the information of said company via a form on a website of a trusted third party;
- vérification des informations de ladite entreprise par le tiers de confiance auprès de sources officielles; - verification of the said company's information by the trusted third party from official sources;
- stockage des informations vérifiées dans une base de données dudit tiers de confiance; storing the verified information in a database of said trusted third party;
- envoi d'un sceau dynamique par le tiers de confiance à l'entreprise - sending a dynamic seal by the trusted third party to the company
- intégration d'un sceau dynamique sur le site Web de l'entreprise; - embedding a dynamic seal on the company's website;
- redirection d'un utilisateur lorsqu'il clique sur le sceau dynamique via un protocole https vers un serveur d'application appartenant audit tiers de confiance, afin d'extraire des informations de l'entreprise ; - Redirecting a user when he clicks the dynamic seal via an https protocol to an application server belonging to said trusted third party, in order to extract information from the company;
- affichage des informations de l'entreprise via le sceau dynamique sur le site Web. - display of company information via the dynamic seal on the website.
BREVE DESCRIPTION DES FIGURES BRIEF DESCRIPTION OF THE FIGURES
[0018] D'autres caractéristiques, détails, et avantages de l'invention ressortiront à la lecture de la description qui suit, en référence aux figures annexées, qui illustrent : Other features, details, and advantages of the invention will emerge on reading the description which follows, with reference to the appended figures, which illustrate:
- la figure 1 montre l'architecture technique d'un système d'identification dynamique d'un site web d'une entreprise conforme à l'invention; FIG. 1 shows the technical architecture of a system for dynamically identifying a website of an enterprise according to the invention;
- la figure 2 montre le déroulement d'un cas d'utilisation du système de la figure 1 ; - la figure 3 montre le diagramme de séquence pour la partie d'inscription, illustrant les principales interactions entre les différents acteurs et composants du système selon l'invention; et FIG. 2 shows the progress of a use case of the system of FIG. 1; FIG. 3 shows the sequence diagram for the inscription part, illustrating the main interactions between the various actors and components of the system according to the invention; and
- la figure 4 montre le diagramme de séquence pour la partie affichage, illustrant les principales interactions entre les acteurs et composantes du système selon l'invention. FIG. 4 shows the sequence diagram for the display part, illustrating the main interactions between the actors and components of the system according to the invention.
Pour plus de clarté, les éléments identiques ou similaires sont repérés par des signes de référence identiques sur l'ensemble des figures. For the sake of clarity, identical or similar elements are marked with identical reference signs throughout the figures.
DESCRIPTION DETAILLEE DETAILED DESCRIPTION
[0019] La figure 1 montre l'architecture technique du système pour identifier une entreprise par intermédiaire d'un site web 1 appartenant audite entreprise selon le principe de la présente invention. Sur cette figure, nous distinguons plusieurs composants. Un site web 10 appartenant à un tiers de confiance 20 permet à une entreprise 2 de s'inscrire. Ce site web 10 est directement relié au serveur d'application 1 1 . L'entreprise s'enregistre via une plateforme téléphonique. Un conseiller du tiers de confiance rempli un formulaire d'inscription sur le site web 10. Par mesure de sécurité l'entreprise 2 n'a pas d'accès direct au formulaire du site web 10. Un serveur Web 4 appartenant à l'entreprise 2 comprend le site Web 1 . Le deuxième module du système selon l'invention permet l'affichage des informations concernant l'entreprise 2 via un sceau dynamique 3 cliquable intégré au site web 1 . Un utilisateur 30, via un navigateur 31 , se connecte au site Web 1 et peut vérifier l'état dudit site Web 1 via le sceau dynamique 3 cliquable intégré audit site Web 1 . En cliquant sur ledit sceau dynamique 3, l'utilisateur 30 est redirigé vers un serveur d'application 1 1 appartenant au tiers de confiance 20. Ledit serveur d'application 1 1 se connecte à un serveur de données 13 pour accéder à une base de données 12 et y extraire les informations vérifiées de l'entreprise 2. Lesdites informations sont alors visibles pour l'utilisateur 30 qui peut ainsi vérifier l'état d'activité de la structure propriétaire du site Web 1 de l'entreprise 2. [0020] Dans ce système, le sceau dynamique 3 permet l'interaction entre le navigateur d'un utilisateur 30 et le site Web 1 de l'entreprise 2. La connexion entre le navigateur 31 de l'utilisateur 30 et le serveur Web 4 de l'entreprise 2 est effectuée via le protocole http ou https si l'entreprise 2 a sécurisé son serveur 4 à l'aide d'un certificat SSL. La connexion à un site est soit en http, soit en https, selon la présence d'un certificat SSL ou non. De même, le serveur Web 4 de l'entreprise 2 se connecte via le protocole https au serveur d'application 1 1 du tiers de confiance 20. [0019] Figure 1 shows the technical architecture of the system for identifying a company through a website owned by 1 company audits according to the principle of the present invention. In this figure, we distinguish several components. A website 10 belonging to a trusted third party 20 allows a company 2 to register. This website 10 is directly connected to the application server 1 1. The company registers via a telephone platform. A trusted third party advisor filled out a registration form on the website 10. For security reasons company 2 does not have direct access to the form of the website 10. A web server 4 belonging to the company 2 includes the website 1. The second module of the system according to the invention allows the display of information about the company 2 via a dynamic seal 3 clickable integrated to the website 1. A user 30, via a browser 31, connects to the website 1 and can check the status of said website 1 via the dynamic clickable seal 3 integrated in said website 1. By clicking on said dynamic seal 3, the user 30 is redirected to an application server 1 1 belonging to the trusted third party 20. Said application server 1 1 connects to a data server 13 to access a database. The information is then visible to the user 30 who can thus check the state of activity of the structure owner of the website 1 of the company 2. In this system, the dynamic seal 3 allows the interaction between the browser of a user 30 and the website 1 of the company 2. The connection between the browser 31 of the user 30 and the Web server 4 of enterprise 2 is performed via the http or https protocol if enterprise 2 has secured its server 4 with the help of an SSL certificate. The connection to a site is either http or https, depending on the presence of an SSL certificate or not. Similarly, the Web server 4 of the company 2 connects via the https protocol to the application server 1 1 of the trusted third party 20.
[0021]Afin d'extraire des informations enregistrées dans la base de données 12, le serveur d'application 1 1 du tiers de confiance 20 se connecte au serveur de données 13 via une interface commune aux systèmes de base de données, JDBC. Cette interface JDBC permet aux applications installées sur le serveur d'application d'accéder à des sources de données. In order to extract information stored in the database 12, the application server 1 1 of the trusted third party 20 connects to the data server 13 via a common interface to the database systems, JDBC. This JDBC interface allows applications installed on the application server to access data sources.
[0022] L'entreprise 2 peut à tout moment modifier les informations concernant l'état de son activité et de sa structure en adressant un e-mail au tiers de confiance 20. Les informations communiquées par l'entreprise 2 au tiers de confiance 20 sont vérifiées par celui-ci auprès de plusieurs sources d'informations officielles avant d'être stockées dans la base de données 12 dudit tiers de confiance 20 et d'être mises à disposition immédiatement. De plus, le tiers de confiance 20 effectue quotidiennement, auprès desdites sources d'informations officielles, des vérifications des informations stockées dans sa base de données 12. The company 2 can at any time modify the information on the state of its business and its structure by sending an e-mail to the trusted third party 20. The information provided by the company 2 to the trusted third party 20 are verified by it from several sources of official information before being stored in the database 12 of said trusted third party 20 and be made available immediately. In addition, the trusted third party 20 carries out daily, from said sources of official information, checks of information stored in its database 12.
[0023] Par ailleurs, le serveur de données 13 est sécurisé afin de garantir l'intégrité des données stockées. De plus, un certificat SSL est mis en place afin de sécuriser la transaction entre le tiers de confiance 20 et le navigateur web 31 de l'utilisateur internaute. Moreover, the data server 13 is secure in order to guarantee the integrity of the stored data. In addition, an SSL certificate is set up to secure the transaction between the trusted third party 20 and the web browser 31 of the Internet user.
[0024] En effet un certificat SSL est installé sur un serveur du tiers de confiance, ledit certificat permet de sécurisé les échanges d'informations avec le navigateur de l'utilisateur. La possession d'un certificat SSL par le tiers de confiance implique les faits suivants: - les transmissions des données entre le navigateur et le site web sont cryptées; et - l'autorité de certification (OpenTrust) émettrice des certificats est authentifiée et reconnue sur les navigateurs. Indeed an SSL certificate is installed on a trusted third party server, said certificate allows secure information exchange with the browser of the user. The possession of an SSL certificate by the trusted third party implies the following facts: - the transmission of data between the browser and the the website are encrypted; and the certificate issuing authority (OpenTrust) is authenticated and recognized on the browsers.
[0025] La figure 2 montre le déroulement d'un cas d'utilisation du système de la figure 1 . Dans une première étape, l'entreprise 2 remplit à l'aide d'un conseiller, le formulaire d'inscription 100 sur le site web 10 du tiers de confiance 20. L'entreprise 2 enregistre 101 et transmet les informations concernant l'état d'activité de sa structure audit tiers de confiance. La vérification 102 des informations se met en place par le tiers de confiance 20 auprès des sources officielles. Au cas où ces informations ne correspondent pas totalement aux données enregistrées sur les sources officielles, une demande de mise à jour 103 est envoyée à l'entreprise 2 (client). Si la vérification échoue, un e-mail 104 est envoyé au client 2 par le tiers de confiance 20 pour l'informer de la situation, dans le cas contraire, les informations seront stockées dans la base de données 12 du tiers de confiance 20 et le sceau dynamique 3, sous la forme d'un programme livrable 3', est envoyé à l'entreprise 2. L'entreprise intègre 107 le sceau dynamique 3 sur son site Web 1 . Le tiers de confiance met à disposition des utilisateurs 30 les informations sur la structure propriétaire du site Web 1 de l'entreprise 2. Lorsqu'un utilisateur 30 clique 105 sur le sceau dynamique 3, affiché sur le site Web 1 de l'entreprise 2, une requête 106 est envoyée au tiers de confiance 20 qui fournit 1 12 ainsi les informations stockées concernant l'entreprise 2. Lesdites informations fournit 1 12 sont envoyées 108 par ledit tiers de confiance à l'utilisateur 30. Figure 2 shows the progress of a use case of the system of Figure 1. In a first step, the company 2 fills out with the assistance of a counselor, the registration form 100 on the website 10 of the trusted third party 20. The company 2 records 101 and transmits the information concerning the state of its structure to this trusted third party. Verification 102 of the information is set up by the trusted third party 20 from official sources. In case this information does not fully correspond to the data recorded on the official sources, a request for update 103 is sent to the company 2 (client). If the verification fails, an e-mail 104 is sent to the client 2 by the trusted third party 20 to inform him of the situation, otherwise the information will be stored in the database 12 of the trusted third party 20 and the dynamic seal 3, in the form of a 3 'deliverable program, is sent to the company 2. The company integrates 107 the dynamic seal 3 on its website 1. The trusted third party makes available to the users 30 the information on the structure that owns the website 1 of the company 2. When a user clicks 105 on the dynamic seal 3, displayed on the website 1 of the company 2 a request 106 is sent to the trusted third party 20 which thus provides the stored information relating to the enterprise 2. Said information provides 11 are sent 108 by said trusted third party to the user 30.
[0026] La figure 3 montre le diagramme de séquence du module d'inscription de l'entreprise 2 sur le site du tiers de confiance 20, illustrant les principales interactions entre l'entreprise 2 et le tiers de confiance 20. L'entreprise 2 s'enregistre 101 sur le site Web 10 du tiers de confiance, les informations concernant son état d'activité, ces informations sont vérifiées 102 par le tiers de confiance 20 puis sauvegardées 1 1 1 dans la base de données 12 du tiers de confiance via le serveur d'application 1 1 . Enfin, le code source du sceau dynamique 3 est envoyé à l'entreprise 2, depuis le serveur d'application 1 1 , avec toutes les documentations nécessaires à son déploiement et à son utilisation. [0027] La figure 4 montre le diagramme de séquence du module d'affichage et les principales interactions entre un utilisateur 30, le sceau dynamique 3 et le tiers de confiance 20. En effet, lorsqu'un utilisateur 30 souhaite consulter le site Web 1 de l'entreprise 2, il clique 105 sur le sceau dynamique 3 intégré sur ledit site Web 1 , une requête 106 est envoyée au serveur d'application 1 1 du tiers de confiance qui, après traitement, envoie une réponse 1 10 au sceau dynamique 3. Ledit sceau dynamique 3 renvoie 108 les données contenues en base 12 à l'utilisateur 30. Figure 3 shows the sequence diagram of the registration module of the company 2 on the site of the trusted third party 20, illustrating the main interactions between the company 2 and the trusted third party. is registered 101 on the website 10 of the trusted third party, the information concerning its state of activity, this information is verified 102 by the trusted third party 20 and then saved 1 1 1 in the database 12 of the trusted third party via the application server 1 1. Finally, the source code of the dynamic seal 3 is sent to the company 2, from the application server 1 1, with all the documentation necessary for its deployment and its use. Figure 4 shows the sequence diagram of the display module and the main interactions between a user 30, the dynamic seal 3 and the trusted third 20. Indeed, when a user 30 wishes to consult the website 1 of the company 2, it clicks 105 on the dynamic seal 3 integrated on said Web site 1, a request 106 is sent to the application server 1 1 of the trusted third party which, after processing, sends a response 1 10 to the dynamic seal 3. Said dynamic seal 3 returns 108 the data contained in base 12 to the user 30.
[0028] De façon préférée, le développement des modules d'inscription et d'affichage se base sur l'architecture MVC et s'effectue sous la plateforme J2EE, ce qui permet d'isoler différentes couches applicatives. Preferably, the development of registration and display modules is based on the MVC architecture and is performed under the J2EE platform, which allows to isolate different application layers.
[0029] Le système est capable de vérifier des informations en se basant sur plusieurs sources officielles d'informations afin d'assurer la véracité des informations délivrées. De plus, la disponibilité et l'accessibilité est garantie pour un grand nombre de connections simultanées. The system is able to verify information based on several official sources of information to ensure the veracity of the information provided. In addition, availability and accessibility is guaranteed for a large number of simultaneous connections.
[0030] De manière générale, le système a pour objectif d'afficher des informations sur la structure propriétaire d'un site Web appartenant à une entreprise. Ces informations renseignent l'état d'activité de ladite structure, en d'autres termes, cela constitue une véritable carte d'identité de l'entreprise. Autrement dit, le système a pour vocation d'informer l'utilisateur de l'état d'activité d'une entreprise via une icône installée sur le site web de ladite entreprise. Un utilisateur se retrouve sur un espace sécurisé lorsqu'il clique sur le sceau dynamique car le système est installé sur un serveur d'application sécurisé par un certificat SSL. Le site web de l'entreprise sur lequel le sceau dynamique est installé peut, lui aussi, être sécurisé par un certificat SSL dans ce cas, le système d'identification selon la présente invention permet d'afficher des informations sur le niveau de sécurité de ce dernier, (affichage des données du certificat SSL). In general, the system aims to display information on the owner structure of a website belonging to a company. This information informs the state of activity of said structure, in other words, it is a real identity card of the company. In other words, the system is intended to inform the user of the state of activity of a company via an icon installed on the website of said company. A user finds himself on a secure space when he clicks on the dynamic seal because the system is installed on a secure application server by an SSL certificate. The website of the company on which the dynamic seal is installed can also be secured by an SSL certificate in this case, the identification system according to the present invention can display information on the security level of the latter, (display of the SSL certificate data).
[0031] La présente invention concerne en outre un procédé d'identification dynamique d'un site Web mis oeuvre dans le système ci-dessus et comprenant notamment les étapes d'inscription et d'enregistrement d'une entreprise auprès d'un tiers de confiance. Ledit tiers de confiance vérifie les informations enregistrées auprès des sources officielles. Ensuite, il stocke les informations enregistrées qui ont été vérifiées dans sa base de données 12. Le tiers de confiance envoie une copie 3' d'un sceau dynamique 3 à l'entreprise 2. L'intégration du sceau dynamique 3 sur le site web 1 de l'entreprise 2 se fait soit par une installation manuelle dudit sceau dynamique via une personne appartenant au tiers de confiance ou bien par intermédiaire d'un prestataire de l'entreprise 2 ayant créé ou chargé de la maintenance du site Web 1 . Un utilisateur qui consulte le site Web 1 de l'entreprise 2 peut vérifier l'état d'activité de ladite entreprise en cliquant sur le sceau dynamique 3. The present invention further relates to a dynamic identification method of a website implemented in the above system and including the steps of registration and registration of a company with a trusted third party. The trusted third party verifies the information registered with the official sources. Then, it stores the recorded information that has been verified in its database 12. The trusted third party sends a 3 'copy of a dynamic seal 3 to the company 2. The integration of the dynamic seal 3 on the website 1 of the company 2 is done either by a manual installation of said dynamic seal via a person belonging to the trusted third party or through a provider of the company 2 having created or responsible for the maintenance of the website 1. A user who consults the website 1 of the company 2 can check the status of activity of said company by clicking on the dynamic seal 3.
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR1453869 | 2014-04-29 | ||
| FR1453869 | 2014-04-29 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2015166185A1 true WO2015166185A1 (en) | 2015-11-05 |
Family
ID=51659715
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/FR2015/051151 Ceased WO2015166185A1 (en) | 2014-04-29 | 2015-04-28 | System for identifying a company by means of the website thereof |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2015166185A1 (en) |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020152134A1 (en) * | 2001-04-12 | 2002-10-17 | Mcglinn Thomas A. | System and method for protecting internet consumers and for certifying, identifying, segregating and locating traditional "brick and mortar" merchant businesses on the internet |
| WO2013188700A2 (en) * | 2012-06-13 | 2013-12-19 | Jp Communications, Inc. | Systems and methods for processing requests for merchant information |
-
2015
- 2015-04-28 WO PCT/FR2015/051151 patent/WO2015166185A1/en not_active Ceased
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020152134A1 (en) * | 2001-04-12 | 2002-10-17 | Mcglinn Thomas A. | System and method for protecting internet consumers and for certifying, identifying, segregating and locating traditional "brick and mortar" merchant businesses on the internet |
| WO2013188700A2 (en) * | 2012-06-13 | 2013-12-19 | Jp Communications, Inc. | Systems and methods for processing requests for merchant information |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP2020522152A (en) | Computer-implemented method, system and computer program product forming a blockchain for public scientific research (blockchain for public scientific research) | |
| US10693839B2 (en) | Digital media content distribution blocking | |
| US20130297973A1 (en) | Automated Conformance and Interoperability Test Lab | |
| FR2950214A1 (en) | User profile data e.g. person's age, verification request receiving method for communication network system, involves receiving return message including user profile data accompanied with marker representative data certification | |
| CA2977899C (en) | Secure transfer of authentication information | |
| Bélanger et al. | POCKET: A tool for protecting children's privacy online | |
| Mahmoud et al. | Towards a comprehensive analytical framework for smart toy privacy practices | |
| FR3048530A1 (en) | OPEN AND SECURE SYSTEM OF ELECTRONIC SIGNATURE AND ASSOCIATED METHOD | |
| US9407654B2 (en) | Providing multi-level password and phishing protection | |
| US11262990B2 (en) | Application topology discovery | |
| Dykstra et al. | Forensic collection of electronic evidence from infrastructure-as-a-service cloud computing | |
| Brinson et al. | Dark Web Forensics: An investigation of tracking dark web activity with digital forensics | |
| FR3076383A1 (en) | SERVICE BROKER FOR CLOUD FOUNDRY PLATFORM | |
| WO2015166185A1 (en) | System for identifying a company by means of the website thereof | |
| EP3136354B1 (en) | Method for securing and ensuring the auditability of an electronic vote | |
| EP3032423B1 (en) | Method and system for validating performance test scenarios | |
| WO2019121674A1 (en) | System and method for configuring a video surveillance infrastructure | |
| WO2018211180A1 (en) | Method for connecting equipment to the internet network | |
| FR2997204A1 (en) | METHOD FOR DOWNLOADING AT LEAST ONE COMPONENT SOFTWARE IN A COMPUTER APPARATUS, COMPUTER PROGRAM PRODUCT, COMPUTER APPARATUS AND COMPUTER SYSTEM THEREOF | |
| EP1627352A1 (en) | Secure computer network system for personal data management | |
| EP3832402A1 (en) | Method for secure connection of a watch to a remote server | |
| EP2795524B1 (en) | Method and device for making a computer application secure | |
| Cappellari et al. | A Cloud-Based Data Collaborative to Combat the COVID-19 Pandemic and to Solve Major Technology Challenges. Future Internet 2021, 13, 61 | |
| FR2887717A1 (en) | METHOD OF CREATING AN ECLATE TERMINAL BETWEEN A BASE TERMINAL AND SERIES-CONNECTED EQUIPMENT | |
| CN120639303A (en) | Information security processing method and computer equipment |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15725816 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 15725816 Country of ref document: EP Kind code of ref document: A1 |